Enterprise and risk

Turn content and AI policy into a control you can evidence

One attested record that product, legal, security and risk teams can all read — and that an auditor can check without taking your word for it.

It matters because…

Policy without evidence is an assertion

Most organisations can describe their AI and content policy. Far fewer can demonstrate it was applied to a specific artifact on a specific date.

Obligations are already operative

California SB 942 as amended, EU AI Act Article 50 and China's labelling measures all apply now, with further dates landing in 2027.

Four teams, four different questions

Legal wants defensibility, security wants integrity, product wants no friction, risk wants coverage. One attested record answers all four from the same artifact.

What gets attested

Marketing and brand assets

Everything published under your name, with a manifest naming the organizational identity behind it rather than whichever agency produced it.

AI-generated output

Machine-readable disclosure on synthetic content, produced as a by-product of generating it.

Internal records

Documents and reports where the question "has this been altered" needs a better answer than file metadata.

Plugs into: Content management and DAM · Marketing and creative pipelines · AI platforms and model endpoints · Existing identity and key infrastructure

What changes once it runs

01

Auditable by default

Every manifest carries who, what, when and under which policy, in a machine-readable form a third party can check.

02

Governance that does not fragment

One policy engine and credential store as coverage expands from media into software and workloads.

03

No proprietary lock-in

Written to published specifications, so the record stays verifiable with or without us.

Most organisations are more than one

Provenance is only as good as its governance.

Tell us what you have to stand behind and who has to be satisfied.